Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-51956

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Grashjs Atlas CMMS 在 v1.6.0 之前的版本中存在“破碎的对象级别授权”(Broken Object Level Authorization,BOLA)漏洞。来自某一租户的已认证用户,仅通过修改 端点中的数字 ID,即可读取并修改其他租户的公司记录。由于应用程序在访问或更新公司对象时未强制执行租户级别的所有权检查,从而允许跨租户访问和修改公司档案数据。

AI Predicted 7.5 Difficulty: Easy

Possible ATT&CK Techniques 1 AI

T1531 · Account Access Removal

Affected Version Matrix 1

VendorProduct Version RangeStatus
n/a n/a n/a affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-51956

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
A Broken Object Level Authorization vulnerability exists in Grashjs Atlas CMMS prior to v1.6.0. An authenticated user from one tenant can read and modify another tenant's company record by changing only the numeric ID in the /company/{id} endpoint. The application does not enforce tenant-level ownership checks when accessing or updating company objects, allowing cross-tenant access and modification of company profile data.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2026-51956

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-51956

登录查看更多情报信息。

Patches & Fixes for CVE-2026-51956 (1)

Proof of Concept for CVE-2026-51956 (1)

Security Blog Posts for CVE-2026-51956 (1)

Same Patch Batch · n/a · 2026-09-01 · 36 CVEs total

CVE-2026-84423 7.3 HIGH Casdoor upload-resource API resource.go missing authentication
CVE-2026-51788 cleverange_auth 0.1.10 远程服务中断漏洞
CVE-2026-51761 TOTOLINK T6 4.1.5 更新LAN IP时存在访问控制缺陷
CVE-2026-51765 TOTO LINK T6 4.1.5:MQTT间接网格信息访问控制缺陷
CVE-2026-51768 TOTOLINK T6 4.1.5 MQTT越权控制漏洞
CVE-2026-51769 TOTOLINK T6 4.1.5cu.748 MQTT访问控制缺陷
CVE-2026-51770 TOTOLINK T6 4.1.5cu.748 MQTT未认证访问控制缺陷
CVE-2026-51767 TOTOLINK T6 4.1.5cu.748 未授权访问控制漏洞
CVE-2026-51934 Tenda A18 v.15.13.07.09 缓冲区溢出漏洞
CVE-2026-51760 TOTOLINK T6 4.1.5 MQTT未认证访问控制漏洞
CVE-2026-52023 Kamailio 6.1.1 之前版本 DoS 漏洞
CVE-2026-52022 Kamailio 6.1.1 之前版本远程拒绝服务漏洞
CVE-2026-52131 llama.cpp b5693 存在可触发的断言漏洞
CVE-2026-52111 fast-note-sync-service<=2.13.7 管理端点认证密钥泄露致权限提升
CVE-2026-52130 llama.cpp b5693 之前版本 JSON转语法递归DoS
CVE-2026-51974 Fooocus 2.5.5 eval注入漏洞
CVE-2026-52132 llama.cpp指定提交前/rerank负top_n致拒绝服务
CVE-2026-52295 FFmpeg 7.0及以上版本缓冲区溢出漏洞
CVE-2026-51750 TOTOLINK T6 4.1.5 未认证访问控制缺陷
CVE-2026-51742 TOTOLINK T6 4.1.5 访问控制不当漏洞

Showing top 20 of 36 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-51956

No comments yet


Leave a comment